AI · 63 giorni fa
Il punto non è più l’uso dell’AI in sé. Il punto è che molti agenti entrano nei sistemi con una propria identità persistente, spesso con privilegi già pronti: se quell’identità viene rubata, l’attaccante si muove come un dipendente o come un’automazione fidata, non come un semplice utente di passaggio.
Le fonti descrivono una crescita rapida degli agenti AI in azienda e un divario evidente tra adozione e governance. Sophos segnala che identità, OAuth token, credenziali di servizio e accessi ai sistemi core sono diventati bersagli ad alto valore; BeyondTrust cita un aumento del 466,7% degli agenti attivi in un anno, segno che la superficie esposta cresce più in fretta dei controlli.
Per chi gestisce copilots, bot e integrazioni che leggono mail, documenti o codice e poi agiscono, queste identità vanno trattate come asset primari. Il controllo approvativo sull’app non basta se restano aperti token e account di servizio che possono ancora attraversare sistemi e flussi di lavoro.
3 fonti che coprono questa storia
Shadow AI agents are multiplying. Here's how to find and secure them.
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility.
AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security
Learn why shadow AI is creating new security risks, how it spreads across enterprises, and why visibility is essential for AI governance.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-07-24